CVE-2008-5524
NONE EPSS 77.6%
Published Dec 12, 200817y ago · Modified Jun 16, 20262w ago
Published Dec 12, 2008 17y ago
Last Modified Jun 16, 2026 2w ago
Description
CAT-QuickHeal 10.00 and possibly 9.50, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
Threat Intelligence
EPSS Exploit Probability
77.6% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-20 Improper Input Validation Validation
Affected Products 4
References 4
- securityreason.com http://securityreason.com/securityalert/4723
- securityfocus.com http://www.securityfocus.com/archive/1/498995/100/0/threaded
- securityfocus.com http://www.securityfocus.com/archive/1/499043/100/0/threaded
- exchange.xforce.ibmcloud.com https://exchange.xforce.ibmcloud.com/vulnerabilities/47435
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.